CVE-2025-2784
HIGH severity · CVSS 7 · Out-of-bounds read
7CVSS HIGH
Summary
A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.
Impact & exploitability
Attack vectorNetwork
Attack complexityHigh
Privileges requiredNone
User interactionNone
Confidentiality impactLow
Integrity impactLow
Availability impactHigh
Exploit probability (EPSS)1%
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Additional information
- NVD record
- https://access.redhat.com/errata/RHSA-2025:21657
- https://access.redhat.com/errata/RHSA-2025:7505Advisory
- https://access.redhat.com/errata/RHSA-2025:8126Advisory
- https://access.redhat.com/errata/RHSA-2025:8132Advisory
- https://access.redhat.com/errata/RHSA-2025:8139Advisory
- https://access.redhat.com/errata/RHSA-2025:8140Advisory
- https://access.redhat.com/errata/RHSA-2025:8252Advisory
- https://access.redhat.com/errata/RHSA-2025:8480Advisory